Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,020cataloged exploits
35,276CVEs with public exploitation
24,695lab-tested
22,166 exploits
ReferênciaVexDay Proof
Mole Group Taxi Calc Dist Script - Authentication Bypass
CVE-2008-6484webappsphp
SQL injection vulnerability in login.php in Mole Group Taxi Map Script (aka Taxi Calc Dist Script) allows remote attacke
23RISK
open
ReferênciaVexDay Proof
Quake 3 Engine Client - 'CG_ServerCommand()' Remote Overflow
CVE-2006-3400doswindows
Stack-based buffer overflow in the CG_ServerCommand function in Quake 3 Engine as used by Soldier of Fortune 2 (SOF2MP)
23RISK
open
ReferênciaVexDay Proof
SoftComplex PHP Image Gallery - 'ctg' SQL Injection
CVE-2008-6485webappsphp
SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery allows remote attackers to execute arbitrary S
23RISK
open
ReferênciaVexDay Proof
DigiAffiliate 1.4 - Authentication Bypass
CVE-2008-6487webappsasp
Multiple SQL injection vulnerabilities in login.asp in Digiappz DigiAffiliate 1.4 and earlier allow remote attackers to
23RISK
open
ReferênciaVexDay Proof
Shader TV (Beta) - Multiple SQL Injections
CVE-2008-6641webappsasp
Multiple SQL injection vulnerabilities in Shader TV (Beta) allow remote authenticated administrators to execute arbitrar
23RISK
open
Referência
CVE-2014-6242
Multiple SQL injection vulnerabilities in the All In One WP Security & Firewall plugin before 3.8.3 for WordPress allow
23RISK
open
ReferênciaVexDay Proof
FluentCMS - 'view.php' SQL Injection
CVE-2008-6642webappsphp
SQL injection vulnerability in view.php in DotContent FluentCMS 4.x allows remote attackers to execute arbitrary SQL com
23RISK
open
Referência
CVE-2014-6271
CVE-2014-6271CRITICALunder attack
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
ReferênciaVexDay Proof
OneCMS 2.5 - Blind SQL Injection
CVE-2008-6652webappsphp
SQL injection vulnerability in asd.php in OneCMS 2.5 allows remote attackers to execute arbitrary SQL commands via the s
23RISK
open
Referência
CVE-2014-6271
CVE-2014-6271CRITICALunder attack
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
Referência
CVE-2009-4560
SQL injection vulnerability in profile.php in WebLeague 2.2.0 allows remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
Simple Machines Forum (SMF) 1.1.6 - Code Execution
CVE-2008-6657webappsphp
Cross-site request forgery (CSRF) vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 be
23RISK
open
Referência
CVE-2014-6271
CVE-2014-6271CRITICALunder attack
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
ReferênciaVexDay Proof
Apartment Search Script - Arbitrary File Upload / Cross-Site Scripting
CVE-2008-6683webappsphp
Cross-site scripting (XSS) vulnerability in listtest.php in Apartment Search Script allows remote attackers to inject ar
23RISK
open
ReferênciaVexDay Proof
Pre ADS Portal 2.0 - Authentication Bypass / Cross-Site Scripting
CVE-2008-6715webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in Pre ADS Portal 2.0 and earlier allow remote attackers to inject a
23RISK
open
ReferênciaVexDay Proof
Pre ADS Portal 2.0 - Authentication Bypass / Cross-Site Scripting
CVE-2008-6716webappsphp
homeadmin/adminhome.php in Pre ADS Portal 2.0 and earlier does not require administrative authentication, which allows r
23RISK
open
Referência
CVE-2009-4561
Multiple SQL injection vulnerabilities in Admin/index.php in WebLeague 2.2.0, when magic_quotes_gpc is disabled, allow r
23RISK
open
ReferênciaVexDay Proof
U&M Software Signup 1.1 - Authentication Bypass
CVE-2008-6717webappsphp
U&M Software Signup 1.0 and 1.1 does not require administrative authentication for all scripts in the admin/ directory,
23RISK
open
ReferênciaVexDay Proof
U&M Software Event Lister 1.0 - Authentication Bypass
CVE-2008-6719webappsphp
U&M Software Event Lister (aka JustListIt) 1.0 does not require administrative authentication for all scripts in the adm
23RISK
open
ReferênciaVexDay Proof
DELTAScripts PHP Links 1.3 - Authentication Bypass
CVE-2008-6720webappsphp
SQL injection vulnerability in admin/adm_login.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
AJ Article 1.0 - Authentication Bypass
CVE-2008-6721webappsphp
SQL injection vulnerability in index.php in AJ Square AJ Article allows remote attackers to execute arbitrary SQL comman
23RISK
open
ReferênciaVexDay Proof
CMScout 2.06 - SQL Injection / Local File Inclusion
CVE-2008-6725webappsphp
Multiple SQL injection vulnerabilities in CMScout 2.06 allow remote authenticated users to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
CMScout 2.06 - SQL Injection / Local File Inclusion
CVE-2008-6726webappsphp
Multiple directory traversal vulnerabilities in CMScout 2.06, when register_globals is enabled, allow remote attackers t
23RISK
open
ReferênciaVexDay Proof
PHPmotion 2.1 - Cross-Site Request Forgery
CVE-2008-6729webappsphp
Multiple cross-site request forgery (CSRF) vulnerabilities in password.php in PHPmotion 2.1 and earlier allow remote att
23RISK
open
ReferênciaVexDay Proof
Flexphplink Pro - Arbitrary File Upload
CVE-2008-6731webappsphp
Unrestricted file upload vulnerability in submitlink.php in FlexPHPLink Pro 0.0.7 allows remote attackers to execute arb
23RISK
open
ReferênciaVexDay Proof
Keller Web Admin CMS 0.94 Pro - Local File Inclusion (2)
CVE-2008-6734webappsphp
Directory traversal vulnerability in Public/index.php in Keller Web Admin CMS 0.94 Pro allows remote attackers to includ
23RISK
open
ReferênciaVexDay Proof
Simple Machines Forum (SMF) 1.1.4 - SQL Injection
CVE-2008-6741webappsphp
SQL injection vulnerability in Load.php in Simple Machines Forum (SMF) 1.1.4 and earlier allows remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
RSMScript 1.21 - Cross-Site Scripting / Insecure Cookie Handling
CVE-2008-6743webappsphp
RSMScript 1.21 allows remote attackers to bypass authentication and gain administrative privileges by setting the verifi
23RISK
open
ReferênciaVexDay Proof
BlogPHP 2.0 - Privilege Escalation / SQL Injection
CVE-2008-6745webappsphp
index.php in BlogPHP 2.0 allows remote attackers to gain administrator privileges via a crafted email parameter in a reg
23RISK
open
Referência
CVE-2009-4569
SQL injection vulnerability in elkagroup Image Gallery allows remote attackers to execute arbitrary SQL commands via the
23RISK
open
previouspage 386 / 739next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.